Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » Cardholder Data

Cardholder Data

Cardholder data (CD) consists of all personally identifiable information (PII), such as the cardholder’s name, card number, expiration date, and CVV security code of the individual with a credit or debit card. This is sensitive card information subject to security regulations like PCI DSS. Banks, payment merchants, and other entities that store and process this data must have adequate security measures to protect the cardholder’s data from security threats. Failure to protect cardholder data can land you in legal problems, and there are financial penalties as well.

Additional reading

Identity and Access Management for Security and Compliance

TL,DR: IAM ensures the right people access the right resources at the right times through authentication (verifying identity) and authorization (determining access permissions). In 2023, 83% of organizations experienced identity-related data breaches Key technologies include Single Sign-On (SSO) for unified access across applications, Multi-Factor Authentication (MFA) for layered verification, Role-Based Access Control (RBAC) for function-based…

Third-Party Risk Management Framework: Steps to Select in 2026

TL,DR: A TPRM framework helps identify, assess, monitor, and reduce third-party vendor risk. Core components include risk identification, assessment, monitoring, mitigation, and continuous security checks. Use it to evaluate vendor exposure across cybersecurity, legal, financial, and operational risk. Over 80% of legal and compliance leaders stated that they discover third-party risks after the initial onboarding…

ISO 27001 Logging and Monitoring Policy: Requirements, Objectives, and Best Practices

TL;DR When systems process sensitive data and users have wide access, it’s critical to know exactly what’s happening, when, and by whom. Logging and monitoring gives you that visibility. It captures every meaningful action including access changes, configuration edits, and data updates, so you can track patterns, investigate issues, and respond with confidence. This isn’t…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.